VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
zxkgxn.exe
Windows Exe (x86-32)
Created at 2019-06-30T09:00:00
Remarks (2/2)
(0x200003a): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zxkgxn.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-06-29 18:14 (UTC+2) |
Last Seen | 2019-06-30 07:49 (UTC+2) |
Names | Win32.Trojan.Stop |
Families | Stop |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x408df7 |
Size Of Code | 0x2fc00 |
Size Of Initialized Data | 0x6ee00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-09-02 03:59:59+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2fabd | 0x2fc00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.73 |
.rdata | 0x431000 | 0x5324a | 0x53400 | 0x30000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.4 |
.data | 0x485000 | 0x14dec | 0x2400 | 0x83400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.65 |
.rsrc | 0x49a000 | 0x5228 | 0x5400 | 0x85800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.56 |
.reloc | 0x4a0000 | 0x2454 | 0x2600 | 0x8ac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.54 |
Imports (2)
»
KERNEL32.dll (110)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HeapReAlloc | 0x0 | 0x431000 | 0x83788 | 0x82788 | 0x2d2 |
GetNativeSystemInfo | 0x0 | 0x431004 | 0x8378c | 0x8278c | 0x225 |
GetNumaProcessorNode | 0x0 | 0x431008 | 0x83790 | 0x82790 | 0x22d |
GetDriveTypeW | 0x0 | 0x43100c | 0x83794 | 0x82794 | 0x1d3 |
WaitForSingleObject | 0x0 | 0x431010 | 0x83798 | 0x82798 | 0x4f9 |
SetTapeParameters | 0x0 | 0x431014 | 0x8379c | 0x8279c | 0x48d |
GetModuleHandleW | 0x0 | 0x431018 | 0x837a0 | 0x827a0 | 0x218 |
ExpandEnvironmentStringsA | 0x0 | 0x43101c | 0x837a4 | 0x827a4 | 0x11c |
WaitNamedPipeW | 0x0 | 0x431020 | 0x837a8 | 0x827a8 | 0x500 |
EnumTimeFormatsA | 0x0 | 0x431024 | 0x837ac | 0x827ac | 0x110 |
LoadLibraryW | 0x0 | 0x431028 | 0x837b0 | 0x827b0 | 0x33f |
Sleep | 0x0 | 0x43102c | 0x837b4 | 0x827b4 | 0x4b2 |
FormatMessageW | 0x0 | 0x431030 | 0x837b8 | 0x827b8 | 0x15e |
GetStringTypeExW | 0x0 | 0x431034 | 0x837bc | 0x827bc | 0x268 |
SetSystemPowerState | 0x0 | 0x431038 | 0x837c0 | 0x827c0 | 0x48a |
GetSystemDirectoryA | 0x0 | 0x43103c | 0x837c4 | 0x827c4 | 0x26f |
CreateMailslotW | 0x0 | 0x431040 | 0x837c8 | 0x827c8 | 0x99 |
WritePrivateProfileStringW | 0x0 | 0x431044 | 0x837cc | 0x827cc | 0x52b |
ReplaceFileA | 0x0 | 0x431048 | 0x837d0 | 0x827d0 | 0x40a |
EnumSystemLocalesA | 0x0 | 0x43104c | 0x837d4 | 0x827d4 | 0x10d |
GetProfileIntA | 0x0 | 0x431050 | 0x837d8 | 0x827d8 | 0x258 |
GetLastError | 0x0 | 0x431054 | 0x837dc | 0x827dc | 0x202 |
GetLongPathNameW | 0x0 | 0x431058 | 0x837e0 | 0x827e0 | 0x20f |
DefineDosDeviceW | 0x0 | 0x43105c | 0x837e4 | 0x827e4 | 0xcd |
MoveFileW | 0x0 | 0x431060 | 0x837e8 | 0x827e8 | 0x363 |
GetFirmwareEnvironmentVariableW | 0x0 | 0x431064 | 0x837ec | 0x827ec | 0x1f7 |
LocalAlloc | 0x0 | 0x431068 | 0x837f0 | 0x827f0 | 0x344 |
FindFirstVolumeMountPointW | 0x0 | 0x43106c | 0x837f4 | 0x827f4 | 0x13e |
GetProfileStringA | 0x0 | 0x431070 | 0x837f8 | 0x827f8 | 0x25c |
HeapLock | 0x0 | 0x431074 | 0x837fc | 0x827fc | 0x2d0 |
GetVolumePathNamesForVolumeNameA | 0x0 | 0x431078 | 0x83800 | 0x82800 | 0x2ac |
GetDefaultCommConfigA | 0x0 | 0x43107c | 0x83804 | 0x82804 | 0x1c9 |
VirtualProtect | 0x0 | 0x431080 | 0x83808 | 0x82808 | 0x4ef |
DeleteCriticalSection | 0x0 | 0x431084 | 0x8380c | 0x8280c | 0xd1 |
GetVolumeNameForVolumeMountPointW | 0x0 | 0x431088 | 0x83810 | 0x82810 | 0x2a9 |
MoveFileWithProgressW | 0x0 | 0x43108c | 0x83814 | 0x82814 | 0x365 |
GetConsoleProcessList | 0x0 | 0x431090 | 0x83818 | 0x82818 | 0x1b1 |
WriteConsoleW | 0x0 | 0x431094 | 0x8381c | 0x8281c | 0x524 |
GetStringTypeW | 0x0 | 0x431098 | 0x83820 | 0x82820 | 0x269 |
ReadConsoleW | 0x0 | 0x43109c | 0x83824 | 0x82824 | 0x3be |
ReadFile | 0x0 | 0x4310a0 | 0x83828 | 0x82828 | 0x3c0 |
OutputDebugStringW | 0x0 | 0x4310a4 | 0x8382c | 0x8282c | 0x38a |
FlushFileBuffers | 0x0 | 0x4310a8 | 0x83830 | 0x82830 | 0x157 |
SetStdHandle | 0x0 | 0x4310ac | 0x83834 | 0x82834 | 0x487 |
EnumSystemLocalesW | 0x0 | 0x4310b0 | 0x83838 | 0x82838 | 0x10f |
HeapFree | 0x0 | 0x4310b4 | 0x8383c | 0x8283c | 0x2cf |
EncodePointer | 0x0 | 0x4310b8 | 0x83840 | 0x82840 | 0xea |
DecodePointer | 0x0 | 0x4310bc | 0x83844 | 0x82844 | 0xca |
GetCommandLineA | 0x0 | 0x4310c0 | 0x83848 | 0x82848 | 0x186 |
RaiseException | 0x0 | 0x4310c4 | 0x8384c | 0x8284c | 0x3b1 |
RtlUnwind | 0x0 | 0x4310c8 | 0x83850 | 0x82850 | 0x418 |
IsDebuggerPresent | 0x0 | 0x4310cc | 0x83854 | 0x82854 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x4310d0 | 0x83858 | 0x82858 | 0x304 |
EnterCriticalSection | 0x0 | 0x4310d4 | 0x8385c | 0x8285c | 0xee |
LeaveCriticalSection | 0x0 | 0x4310d8 | 0x83860 | 0x82860 | 0x339 |
GetStdHandle | 0x0 | 0x4310dc | 0x83864 | 0x82864 | 0x264 |
GetFileType | 0x0 | 0x4310e0 | 0x83868 | 0x82868 | 0x1f3 |
GetStartupInfoW | 0x0 | 0x4310e4 | 0x8386c | 0x8286c | 0x263 |
GetProcessHeap | 0x0 | 0x4310e8 | 0x83870 | 0x82870 | 0x24a |
HeapAlloc | 0x0 | 0x4310ec | 0x83874 | 0x82874 | 0x2cb |
ExitProcess | 0x0 | 0x4310f0 | 0x83878 | 0x82878 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4310f4 | 0x8387c | 0x8287c | 0x217 |
GetProcAddress | 0x0 | 0x4310f8 | 0x83880 | 0x82880 | 0x245 |
AreFileApisANSI | 0x0 | 0x4310fc | 0x83884 | 0x82884 | 0x15 |
MultiByteToWideChar | 0x0 | 0x431100 | 0x83888 | 0x82888 | 0x367 |
WideCharToMultiByte | 0x0 | 0x431104 | 0x8388c | 0x8288c | 0x511 |
HeapSize | 0x0 | 0x431108 | 0x83890 | 0x82890 | 0x2d4 |
CloseHandle | 0x0 | 0x43110c | 0x83894 | 0x82894 | 0x52 |
SetLastError | 0x0 | 0x431110 | 0x83898 | 0x82898 | 0x473 |
GetCurrentThread | 0x0 | 0x431114 | 0x8389c | 0x8289c | 0x1c4 |
GetCurrentThreadId | 0x0 | 0x431118 | 0x838a0 | 0x828a0 | 0x1c5 |
GetModuleFileNameA | 0x0 | 0x43111c | 0x838a4 | 0x828a4 | 0x213 |
WriteFile | 0x0 | 0x431120 | 0x838a8 | 0x828a8 | 0x525 |
GetModuleFileNameW | 0x0 | 0x431124 | 0x838ac | 0x828ac | 0x214 |
QueryPerformanceCounter | 0x0 | 0x431128 | 0x838b0 | 0x828b0 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x43112c | 0x838b4 | 0x828b4 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x431130 | 0x838b8 | 0x828b8 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x431134 | 0x838bc | 0x828bc | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x431138 | 0x838c0 | 0x828c0 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x43113c | 0x838c4 | 0x828c4 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x431140 | 0x838c8 | 0x828c8 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x431144 | 0x838cc | 0x828cc | 0x2e3 |
CreateEventW | 0x0 | 0x431148 | 0x838d0 | 0x828d0 | 0x85 |
GetCurrentProcess | 0x0 | 0x43114c | 0x838d4 | 0x828d4 | 0x1c0 |
TerminateProcess | 0x0 | 0x431150 | 0x838d8 | 0x828d8 | 0x4c0 |
TlsAlloc | 0x0 | 0x431154 | 0x838dc | 0x828dc | 0x4c5 |
TlsGetValue | 0x0 | 0x431158 | 0x838e0 | 0x828e0 | 0x4c7 |
TlsSetValue | 0x0 | 0x43115c | 0x838e4 | 0x828e4 | 0x4c8 |
TlsFree | 0x0 | 0x431160 | 0x838e8 | 0x828e8 | 0x4c6 |
GetTickCount | 0x0 | 0x431164 | 0x838ec | 0x828ec | 0x293 |
CreateSemaphoreW | 0x0 | 0x431168 | 0x838f0 | 0x828f0 | 0xae |
FatalAppExitA | 0x0 | 0x43116c | 0x838f4 | 0x828f4 | 0x120 |
IsValidCodePage | 0x0 | 0x431170 | 0x838f8 | 0x828f8 | 0x30a |
GetACP | 0x0 | 0x431174 | 0x838fc | 0x828fc | 0x168 |
GetOEMCP | 0x0 | 0x431178 | 0x83900 | 0x82900 | 0x237 |
GetCPInfo | 0x0 | 0x43117c | 0x83904 | 0x82904 | 0x172 |
GetConsoleCP | 0x0 | 0x431180 | 0x83908 | 0x82908 | 0x19a |
GetConsoleMode | 0x0 | 0x431184 | 0x8390c | 0x8290c | 0x1ac |
SetFilePointerEx | 0x0 | 0x431188 | 0x83910 | 0x82910 | 0x467 |
SetConsoleCtrlHandler | 0x0 | 0x43118c | 0x83914 | 0x82914 | 0x42d |
FreeLibrary | 0x0 | 0x431190 | 0x83918 | 0x82918 | 0x162 |
LoadLibraryExW | 0x0 | 0x431194 | 0x8391c | 0x8291c | 0x33e |
GetDateFormatW | 0x0 | 0x431198 | 0x83920 | 0x82920 | 0x1c8 |
GetTimeFormatW | 0x0 | 0x43119c | 0x83924 | 0x82924 | 0x297 |
CompareStringW | 0x0 | 0x4311a0 | 0x83928 | 0x82928 | 0x64 |
LCMapStringW | 0x0 | 0x4311a4 | 0x8392c | 0x8292c | 0x32d |
GetLocaleInfoW | 0x0 | 0x4311a8 | 0x83930 | 0x82930 | 0x206 |
IsValidLocale | 0x0 | 0x4311ac | 0x83934 | 0x82934 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x4311b0 | 0x83938 | 0x82938 | 0x29b |
CreateFileW | 0x0 | 0x4311b4 | 0x8393c | 0x8293c | 0x8f |
USER32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetScrollBarInfo | 0x0 | 0x4311bc | 0x83944 | 0x82944 | 0x174 |
LoadAcceleratorsW | 0x0 | 0x4311c0 | 0x83948 | 0x82948 | 0x1e5 |
GetWindowWord | 0x0 | 0x4311c4 | 0x8394c | 0x8294c | 0x1a5 |
OpenWindowStationA | 0x0 | 0x4311c8 | 0x83950 | 0x82950 | 0x22c |
SetPropA | 0x0 | 0x4311cc | 0x83954 | 0x82954 | 0x2ac |
SetDlgItemTextA | 0x0 | 0x4311d0 | 0x83958 | 0x82958 | 0x28f |
GetMessageTime | 0x0 | 0x4311d4 | 0x8395c | 0x8295c | 0x15c |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
zxkgxn.exe | 1 | 0x00400000 | 0x004A2FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678E20 | 0x006BDC4B | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678E20 | 0x006BDC4B | Content Changed | - | 32-bit | 0x0067A22D, 0x00679902 |
![]() |
![]() |
...
|
buffer | 1 | 0x00678E20 | 0x006BDC4B | Content Changed | - | 32-bit | 0x0067A081, 0x00679DF8 |
![]() |
![]() |
...
|
zxkgxn.exe | 1 | 0x00400000 | 0x004A2FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0N28733.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2_-YQaqX40ls7kZnQI.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4hZE9nFAdJv.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6bvJUbgBGTbsIJMKW8.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6igNpwR0pgLT9a.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\75tKv_wPWu nle.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iMKYkmcr3Dm3Fk6ffK.ots | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kP8ULRqZpLx.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OXbBkJHSc.ods | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p41R3hPr.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pAeUc4J9behwUSLh5ZK.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PolmUMHRORMWgP.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qTEbn_aHVk98J.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\q_qr72fTT.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rzNuUzflSMr4Y.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yg5sCFMNs8oiIw.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zxkgxn.exe | Modified File | Binary |
Unknown
|
...
|
»
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
zxkgxn.exe | 1 | 0x00400000 | 0x004A2FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678E20 | 0x006BDC4B | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678E20 | 0x006BDC4B | Content Changed | - | 32-bit | 0x0067A22D, 0x00679902 |
![]() |
![]() |
...
|
buffer | 1 | 0x00678E20 | 0x006BDC4B | Content Changed | - | 32-bit | 0x0067A081, 0x00679DF8 |
![]() |
![]() |
...
|
zxkgxn.exe | 1 | 0x00400000 | 0x004A2FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0Q3LulVoi6BYXkATC.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\30Wm1uP_k08jvj97lQ5Z.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GRA80ibP5ZcjgL2YpVJ.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rUyI.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tGcOKsKW8vY3r.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tgGDARb0KAuLH86cV.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ys koK.xlsx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\NDR1.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\RCBYlf_e4F0CAnTDs_Cv.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\U3NMPiDKOwkRxmiQp.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dQ_0l6.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2U_8PhFaccxBmEGBGe3v.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\5Qd_U17.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\7xg3.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\igFrRTPuZ1KOcff.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\M2Hq1q.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\thMFQm.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\VvaG-iQ-9rXlD9Y.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\LL-t.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\rb8St5qJhaFz.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iN9wXlo7M3\HID JrRHaaXMym.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iN9wXlo7M3\XWPPBA.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\FRhJVbO27hszhEC4EU.odp | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\pCC1nCcN4mL.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\SNg4GRtr2YJUAzJ_6.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tvalSG6kWCd\LJP4K.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\-Bnbr4EKB.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\DD0VSBvifKy.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\mt-NxS9.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\_US29v3kaQayesknOB.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\9I3wBfC.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\gXqHnWD.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\pWM7.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OSKgyoas7znhFe\3J2ydx.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OSKgyoas7znhFe\dbSz.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OSKgyoas7znhFe\XHt9VP7ib.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OSKgyoas7znhFe\_iolZcQAgtC1ACM.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\r-u9vnXsx8Ur0\ampfWs0z5kbstxRZUv.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\r-u9vnXsx8Ur0\HAJ2zHK0.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\r-u9vnXsx8Ur0\lJDyJz4X_LOUsSG.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\r-u9vnXsx8Ur0\Xu0FJPBCEsMrFdRg0wfb.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\r-u9vnXsx8Ur0\y0VZOX.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\cpBN4K954GbZNf.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\GpZ VRAn1yi_-.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\jXsioQ.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\mR73VRvHqMlHdz.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\s-v3cZbpeiJD1yTvhr.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\UAJvNRac055.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\x6E1GbuOZBC_86.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\Zmx9tyz7RoVpEsv00H.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\TB1FXyT70\6ften7Ta9q8fR_DlLE.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\TB1FXyT70\PkQ0fGsu5.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\JfBL0k2cocNOiKXL4y9\-pPGVSgI.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\JfBL0k2cocNOiKXL4y9\f7Iu.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\JfBL0k2cocNOiKXL4y9\_-u6ogOGtJDh_andzkIr.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0X9H7M.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\8RDB7k.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\FtBJIQkicPBzsMWmM5J.rtf | Modified File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
ԅn$lS.(vW;^wY%Aָ&߭3?`zwB)vUk(WȏwߺtPcP_̦ ,Q3u̦]ע,:bRh#r_ďlAȕ`=o] 6Ac~Zꣁ4~9_L0`!uIṄ4fѩwt]?_& VTD뜿:^!^L;UжDOODIz6NJxz!ʖi/+8CJVp1*&huDC=2/T߷LTj-L4jWQV]/*K=0BgV]YgEfJ {A%~Y+Ή|r/kg4H7炸Fh|IW:B$f&%y"/`R(F۫tzұX;(uA&|I_Ȟk߷0NsƊ<)Q?ha/YKg'jBgD`71S2!B0>,iehzQ!In#^'(n=tg&4M5f~qe*H&>wB灝bP+7-~-WD#XwQbR?b hC%SV8]u*RN)Z<`?Pũ#$^fn8njpZɭ^sxڪco?*cgTAckCJ -1a^tҠGrakbkٯ߬4M,vb?CT0/Mh6dt<|C Ũ?C=b؞kn;"Q99Xt!B9$j!SKf,s FWnP0W'wPɚD1g&ZB/!*snFFT.Q7c=r!%o&ڍ+lG+# @J&O?)Bs=vUpؒ9n3fr<4-RXLMq!!7xg"<BÒh+/nSZOT_:.=/&];~Hp7=W%7XpVw<omQJs!/%j.J4HBcܳM*fɇĻZïRϴEhBt+Ʉ,U!ws3wUPԏHZ1ۍ6؇1~!.XNjzWlڕ r!p|Jt(ɮtكbm=*~O5/*TFB6,_^IodBDIY7lKr&ukP~cc|ZlX/CtiimatFy pO'o;0K#QsDYE?ASA-h(_8Qa.Ҭ<NsV)l慠ANuFN'X̽`A6сʣUbqb5LLhKʎ+<WfJM4EBU`s:A'5G1X$"S2gj!Wc3bOSڛ.Oź8VUq/Ϫ&^WYF/PT9n,<V"+y#.Gzn>n(a:3wpҰS[tiv FFi=.aYპ/,MIx56*x6)T,҄YDQ%ux# ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\j3Zk5qyJiGa6pOh.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\TWsD3\0jha7Ez6BS.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\TWsD3\6iJuvel1.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\TWsD3\BR7Cji.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\TWsD3\DQcA9QRfBGkKr w6.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\TWsD3\WAQy.xlsx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tvalSG6kWCd\oJv-O\-RJ_rXnG1_.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\3JFk\sHdKY9oX2.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\3JFk\smH64uN0q8.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\3JFk\ylebE_y3_yj.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\FxgxMEyG6Z\rqr FeHB_E8CueZs9.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\3mMy51V.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\L4TT06vVg0ef.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\WBMmCD2Hu9jcGCg.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\KpZlD4zquX\fQS43pyYf93X_Ex4mvdQ.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\R5ZCMh\EfuTYTPiCx LOe.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\R5ZCMh\F1NPm.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\R5ZCMh\MFCCzusoQ99IUVZOnO.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\WF0f1QmDHo82b2E\RzVVuYwX5ISIAY3GJCd.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\WF0f1QmDHo82b2E\USjQB.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\EVQWdEk.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\FktDzr_Il x_4yzD.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\v3vmN1a.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\02kt3FBU.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\GcIb4JtMTQ.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\hxwsGGSX.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\xdcv4NFG2H1C8.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\7fX2K\jx1kJWZdi iCE.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\7fX2K\Si93eS7jq6X4SJC7vm61.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\_IS6dQkXRiXDfJ5-\ISL0.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\YJf_dR\_IS6dQkXRiXDfJ5-\OIIPvpIKePb.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\WF0f1QmDHo82b2E\X_INggXuIaYsOTYsJW7\4KoQgGe.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\WF0f1QmDHo82b2E\X_INggXuIaYsOTYsJW7\MGGz-2Q618NkS r.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\8gCaS.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\b3vNAE2PVhFDju_7yS.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\d_Y88L0xD5.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\nOS9oi.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\UdyiuRr9KYVW-Px_.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\UyfgKSYNRi6Oyp.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\9tDINHGgROIz00XY.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\qTnRlL.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\tMaPYPi5JgUXP1XW.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\U3-na4Ecc7B.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\w8QtRE0Av57MWN-aHv.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\get[1].php | Downloaded File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ay_t-P.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\C6eN8spyaXs9O5N.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QATxQ8 VuKhKsG6j5boU.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\t1oDIACQ6VZc-ArQIwpX.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0r-zyx2wH0-I.pptx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7okz4Pc-gSuOVu.docx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GfPtWvk5Lmj.xlsx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kpj8t.pptx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KsTqGqqzg.xlsx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OrLlCAU81JJA3-CN.docx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Q4Mi.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\RAIpVw9N67HN.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\TFi_rpFOJSO_vICGfl.docx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\UxVjqI79MHDnp-w7vHYP.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\f1KLA.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\gJEx.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vLbfj.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\PbT_4bgt7AZeNnG57IPC.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iN9wXlo7M3\3yYw8jcr.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iN9wXlo7M3\45N3LRg1kFlD_Qyjf8.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\71f4 4SP91MVI3\pakuYqh.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OSKgyoas7znhFe\3uz9sjygz2I9u-5T7p.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\1XL3nUBpXBByeYM.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\bps8RA.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\IiTufgt.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\LV_qcOmmob.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\TB1FXyT70\8ndf-ek48BAm.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\TB1FXyT70\SGPp8BH7eiOdE.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\TB1FXyT70\u5VpH1Gfjec38H3.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eyzvk3aytLrTvd\TB1FXyT70\wCHfAt0k5.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\JfBL0k2cocNOiKXL4y9\Dk-mCKfeMJ.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\JfBL0k2cocNOiKXL4y9\hv8Rvu6GKv.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\JfBL0k2cocNOiKXL4y9\VoZWZdD.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\e6btBcfWeC9TI4.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tvalSG6kWCd\oJv-O\vDiwpl_QLurQQz6.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\3JFk\v _P9.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\FxgxMEyG6Z\NiLbAzC1YwUFTvZqU.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zTvNij62y31ygD\FxgxMEyG6Z\VpT_TcidUDkQuxNiXW9.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\KpZlD4zquX\Mw3Rg1vX.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\KpZlD4zquX\oWuD6cFhx.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\nEqZA\R5ZCMh\LyCXLD1At.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\mmUH6saj5D04se1Ny.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0cFh2o\4fiD3H F26C.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0cFh2o\FF1E_qOk_q3b2hS6Wq.odt | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\1rim73kXzbZdPVb.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\QUfuVrMTFwGhP.odt | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\38Tocm\RrMc-y7gilA\0hH2Yg pWVEr\WPd8.docx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\4t8dP5RHOtB8TtLqW.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\M1Ow pK RUoG\sd3L87.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\gpNfbjz4.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\b-b9YkzIMqBbLX\FlfRA9\16cC5\VAY0f6Tek5y2drs\y3s8jy4WEuwL8.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.litar | Dropped File | Unknown |
Not Queried
|
...
|
»